The recent arstechnica article ( about the report on Matrix security vulnerabilities revealed disagreement between the researchers and the vendor.
This is not unusual, but it is unnecessary and damaging (usually for the vendor).

I've told my taking down a data center with regex typo before. How about the time I hastily wrote a HTTP over RPC proxy in C++ and deployed it to prod because HTTP access to prod from corp was being turned off. I broke all monitoring of prod from corp.


FYI: I'll be posting a job description for a Corporate Security Engineer/Architect role at Oxide very soon. One of our short-term needs is experience setting up internal PKI for code signing and internal services. Spread the word.

First part of the review of UP 4000 x86 credit card-sized with an Atom x7-E3950 quad-core processor, 4GB RAM, 64GB flash.


